First published: Wed Nov 13 2024(Updated: )
Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Script Security | <1365.1367.va_3b_b_89f8a_95b_>1362.1364.v4cf2dc5d8776<=1367.vdf2fc45f229c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2326034 is considered critical due to the lack of permission checks that allow attackers to access sensitive information.
To fix REDHAT-BUG-2326034, update the Jenkins Script Security Plugin to version 1365.1367.va_3b_b_89f8a_95b_ or ensure you are running versions earlier than 1362.1364.v4cf2dc5d8776.
The affected product by REDHAT-BUG-2326034 is the Jenkins Script Security Plugin versions 1367.vdf2fc45f229c and earlier.
The risks associated with REDHAT-BUG-2326034 include unauthorized attackers being able to verify file existence, potentially leading to further exploitation.
Attackers with Overall/Read permission can exploit the vulnerability in REDHAT-BUG-2326034 to check the existence of files on the console.